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Abstract 

In quantum cryptography the optimal eavesdropping strategy requires that the eaves- 
dropper uses quantum memories in order to optimize her information. What happens if 
the eavesdropper has no quantum memory? It is shown that the best strategy is actually 
to adopt the simple intercept /resend strategy. 



1 Introduction 

With the development of quantum information theory, traditional quantum state 
discrimination has, in many cases, been given a twist. It is no longer just the simple 
question of identifying one state drawn from a known set of states. Often there 
is additional information available after the interaction with the 'unknown' system 
or even after the measurement has been performed. For example, in the BB84 
protocol P for quantum cryptography [2] the eavesdropper, Eve, knows that the 
quantum system is prepared with equal probability in a states belonging to a set 
of states made by two mutually unbiased bases. Moreover, she knows that after 
her eavesdropping, i.e. after the interaction with the 'unknown' quantum state, she 
will learn in which basis the system was originally prepared. She then uses this 
additional classical information, to gain more information about the initial state. 

For the BB84 protocol, the optimal eavesdropping strategy pi,, consists in in- 
tercepting the system prepared by Alice, attach an ancilla and let the combined 
system undergo a unitary interaction. After the interaction the original system is 
forwarded to Bob, whereas Eve keeps the ancilla. In this way she can transfer some 
of the information about the original state to her ancilla, with the cost of disturbing 
the original state and hence introduce errors on Bob's part. The more information 
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Eve transfers to her own system, the more she is disturbing the original system 
and the higher error rate she is introducing. In order for Eve to get the maximum 
information out of her ancilla, it is usually assumed that she does not measure her 
ancilla until after the public discussion between Alice and Bob. In this way she can 
use the knowledge that she gains by passively listening to the public discussion to 
select the measurement best suited for each ancilla. However, this requires that Eve 
is able to store her ancilla for a certain amount of time in a quantum memory. Here 
we ask the question, what happens if Eve does not have a quantum memory? 

In this paper we consider the standard BB84 protocol pQ for qubits and discuss 
basically two different scenarios: the simple intercept /resend eavesdropping |4 and 
eavesdropping using an ancilla — but without a quantum memory. In both cases 
we consider a range of von Neumann measurements. 

The scenario which is considered here is very simple, but the underlying question 
is both important and interesting because it concerns not only eavesdropping, but a 
much more general scenario: What happens when state discrimination is combined 
with additional classical information? What is the optimal measurement, when 
there later will be given additional classical information? These are questions which 
are interesting to consider in full generality. The study made in this paper should 
be considered only the beginning. 



2 Intercept /resend eavesdropping 

Consider the BB84 protocol for qubits, which uses two mutually unbiased bases for 
the secret key creation. We assume that Alice and Bob use the x and the y-basis, 
and use of the following definition of the states, 

|*±> = -^(|0)±|1» and |y±> = -^(|0>±i|l» (1) 

here expressed in the computational basis | ) and | 1 ) . 

First we will consider intercept / resend eavesdropping, which historically also was 
the first eavesdropping strategy to be considered. This strategy requires no quantum 
memories, and it is reviewed in order to compare with the optimal eavesdropping 
strategy without quantum memory. It consists very simply in Eve intercepting the 
qubit prepared by Alice while in transit to Bob, she then estimates the state of 
the qubit by means of a measurement, and prepares a new qubit in the state that 
she found and sends it to Bob. We assume that Eve performs a von Neumann 
measurement lying in the xy-plane 1 . It is possible to consider all measurement 

In higher dimension it will be necessary to consider POVMs [1] 
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Figure 1: Here is shown the x and the y basis and the two measurement bases used by Eve, 
and 0'. Notice that the states are drawn on the equator of the Poincare sphere. 



strategies of this kind in one go, by parameterizing the measurement as follows: 

|+0) = -L(|O> + e *|l» and | _^) = -L(| )- e *|l», (2) 

where G [0, 7r/4]. Since this measurement is not symmetric with respect to the two 
bases, Eve will have different fidelities and disturbances in the two bases, moreover 
she will also introduce different error rates in the two bases. However, it is easy 
to restore the symmetry by letting Eve choose at random between two different 
measurements: namely the 0-measurement and the measurement which corresponds 
to 0' = 7r/2 — (see fig. 1). Notice that this symmetrization doesn't change Eve's 
average information. When performing the or 0' measurement, Eve will obtain 
the following fidelities and disturbances in the two bases: 

n* = *%j = \o- +<**</>) > ^ = £i,^(i-cos0) 

Fl* = Flv = \(1 + sin 0) , Z^ = Z^, = i(l-sin0) (3) 
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Where as usual we have F E ^ + D l E . = 1. 

Independently of whether Eve measures in the or the 0'-basis, half of the times 
Alice has prepared the qubit in the x-basis, and half of the time she has prepared 
the qubit in the y-basis. Eve obtains the following amount of Shannon information 
0, respectively 

^ = Ikv = 1 + F X E4 10 § F E4 + D l4> lQ g D %<t> 

^ = = 1 + log F%* + D h<p log Dl >(j> . (4) 

This means that Eve's average information is 

Ib=\(I%j + I V bj + I%j + 1 V bj,). (5) 

After her measurement Eve has to prepare a new qubit and send it to Bob. However, 
at this point in the protocol Eve doesn't know in which basis the original qubit was 
prepared. We consider the usual case where she prepares the same state that she 
found by her measurement and sends that to Bob. 

Assuming that Eve measures in the basis, then the fidelity and disturbance 
which Bob finds, can be obtained by the following argument: with probability F E ^, 
i = x,y, Eve will find the correct guess state and send it to Bob; where correct 
guess state means that if Alice sent a + state then Eve will identify the state as the 
+0, etc. Assuming that Bob measures in the same basis as Alice, he will then have 
probability F E ^ of obtaining the correct state. Whereas with probability D l E ^ Eve 
finds the wrong guess state and hence sends the wrong state to Bob. However, if 
Bob makes the wrong identification of the wrong state, he will actually obtain the 
correct state; this will happen with probability D l E ^. So in total Bob's probability 
for getting the correct state is: 

= (Fi,) 2 + (Di,y = l + c -^ (= n#) 

= (F V e,,) 2 + {D^f = \+ S ^ (= F%#) (6) 

As for Eve, due to symmetry we have F B , = F B ^ and F B ^ = F B ,,. 

Making use of the expressions of Eve's fidelity and disturbance, one finds that 
Bob's overall fidelity Fb,4> = \{F E ^ + F B ^) = 3/4, and disturbance Db,^ — 1 — 
Fb,<p = 1/4 is independent of the measurement performed by Eve. However, if Eve 
doesn't alternate between the two bases and 0', Bob will find different fidelities 
and disturbances in his two bases, see eq.(jHJ). 

There are a couple of special values of which are worth considering more 
explicitly, namely the case = and = 7r/4: The case where = and hence 
0' = 7r/2, corresponds the the situation where Eve is measuring at random in the 
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x and the y-basis, hence using the same bases as Alice and Bob. The information 
that Eve obtains in this situation is so-called deterministic information, becuase 
when the three of them use the same basis, Eve knows the secret bit, whereas if she 
measures in the wrong basis she will no nothing about the bit value. On average 
Eve gains 1/2 a bit of information. 

In the case where = 7r/4, we have a very special situation. In this case the <p- 
measurement and the (//-measurement coincides and Eve no longer needs to choose 
at random between two measurements, since this single measurement treats the 
two bases symmetrically. This particular attack in known as the intercept /resend 
attack in the intermediate basis [7j. It can be shown that that this measurement 
optimizes Eve's probability of guessing the state correctly independently of the basis. 
Which means that Eve obtains the same amount of information on each single bit. 
However, her information is no longer deterministic, but probabilistic, which means 
that she knows she bit with a certain probability (different from 1). Even if this 
measurement strategy gives Eve less information (Ie « 0.39), than measuring in 
the same basis as Alice and Bob, it is an advantage for Eve, when it is taken 
into account that Alice and Bob later will go through classical error correction and 
privacy amplification This is due to the fact that probabilistic information is 
more robust during this process than deterministic information. 

As a curious point should be mention that the states corresponding to the inter- 
mediate states, also play an optimal role in the game of quantum state targeting jHUH] 
and Bell inequalities |lUj . 

In order to compare with the results in the next section it is useful to display the 
information that Eve obtains as a function of the disturbance that she introduces. 
Eve can lower the disturbance by eavesdropping only on a fraction / e [0, 1] of 
the transmitted qubits, where / = corresponds to no eavesdropping and / = 1 
to eavesdropping on all qubits. Assuming that eavesdropping is the only cause of 
errors, then the disturbance that Alice and Bob will find if Eve only eavesdrop 
on a fraction of the qubits is Db = f • Db,* = |, since D B ^ = D B ^i = 1/4. 
Similarly, Eve's average information becomes / • Ie- It is possible to express Eve's 
information in terms of the disturbance that she creates, since / = 4Db, which 
means Ie{Db) = ^DbIe- The corresponding information curves are displayed in 
figure 2. Notice that the information curves for intercept /resend eavesdropping are 
only defined up til the disturbance Db = 1/4, since this is the disturbance which 
Eve would introduce if she would eavesdrop on each single qubit. Furthermore it 
should be kept in mind that these information curves corresponds to the average 
information on the full key, since Eve obviously has no information when she doesn't 
eavesdrop. 

Since G [0, 7r/4], the two special cases considered above correspond to the end 
points of the interval, changing the parameter will therefore smoothly change the 
information curve from Ie,o = I-E_irxy to Ie.x/4 = I-E_irint, see Fig.2. 
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Figure 2: The information curves as a function of the disturbance detected by Bob: LB = 
Bob's information. For Eve: LEopt = optimal information with quantum memory, I_E_irxy = 
intercept /resend measurement in the x, y bases, I_E_irint = intercept /resend measurement in 
intermediate basis, I_E_optxy = optimal eavesdropping without quantum memory, measurement 
in the x, y bases, I_E_optint = optimal eavesdropping without quantum memory, measurement 
in the intermediate basis. Notice that by changing <fi e [0, vr/4], the information curve smoothly 
goes from I_E_*xy to I_E_*int (see also Fig. 3). 

3 Optimal eavesdropping 

The optimal eavesdropping strategy consists in Eve letting an ancilla undergo a 
unitary interaction with the qubit prepared by Alice, after which she sends on the 
(now disturbed) qubit to Bob and keeps her ancilla. Eve usually stores her ancilla 
in a quantum memory and only performs a measurement on it after she has learnt 
from the public discussion between Alice and Bob in which basis the original qubit 
was prepared. In order to optimize her information Eve has to measure her ancilla 
in same the basis as the qubit was originally prepared. 

When expressed in the computational basis, i.e. the z-basis, the optimal eaves- 
dropping strategy can be written on the following simple, but asymmetric form 

| > | > | 00) 

| 1 > | > -^cosa|10) + sina|01) (7) 

where the lefthandside indicates the state before the interaction and the righthand- 
side the state after the interaction of the qubit sent by Alice and the Eve's ancilla. 
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Figure 3: The bottom curve corresponds to measuring in the intermediate basis (0 = 7r/4) and 
the top curve corresponds to measuring in the x or y basis. 

The fidelities of Bob and Eve are F B — (1 + cosa)/2, and F E — (1 + sina:)/2, 
respectively. The disturbance is Di = 1 — Fi, where i = {B, E}. 

It should be emphasized that with respect to the x and y-basis the eavesdropping 
strategy is symmetric and the fidelities are therefore also the same for the two basis. 
The information curves for Bob and Eve ij = 1 + D,j\og 2 Di + (1 — _Dj)log 2 (l — Di), 
where i = {B, E} are shown in figure 2, where Eve's disturbance has been expressed 
in terms of Bob's disturbance Dg, i.e. De{Db)- However, it should be remembered, 
that in order for Eve to optimize her fidelity and her information Eve has to perform 
her measurement after the public discussion between Alice and Bob, which means 
storing her qubit in a quantum memory. 

We will now consider a situation which is less ideal for Eve — but much more 
realistic as of today — namely where Eve has no possibility of storing her ancilla in 
a quantum memory and therefore has to make a measurement right a way. As in the 
case of intercept /resend eavesdropping, Eve will still listen to the public discussion 
between Alice and Bob, because even if the information about the original basis 
preparation of the qubit arrives after she has performed her measurement she can 
still use the information to make an interpretation of her measurement result and 
obtain more information. 

Consider again the situation where Eve measures with equal probability in either 
the or the 4>' basis. Then, if she has let her ancilla undergo the interaction 
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described in eq.(J7J), she will have the following measurement fidelity and disturbance: 



f e,4>= ^ + cos(^sma) , D X E4> = - (1 - cos <p sin a) 

F E,<t>= ^(l + sin0sina) , D E>4> = -(1 - sin0sina) (8) 

Where as usual we have F E ^ + D E ^ = 1, and again due to symmetry (see figure 1) 
D E ± = D V E ^, and D V E ^ = D E ^,. Bob's fidelity and disturbance do not change. 

Based on the obtained fidelity and disturbance, the information can be computed 
I E (D B ) = \{I{D%) + I{DD + I(D%) + I{p^)). The resulting information curves 
in the range G [0, 7r/4] are shown in Fig. 2 and 3. 



4 Conclusion 

When looking at the curves in figure 2, one would conclude that if Eve does not 
possess a quantum memory, then the best that she can do is to resolve to inter- 
cept/resend eavesdropping. However, one should be careful about drawing conclu- 
sions from figure 2 alone. It should be remembered that in order to be able to 
draw the curve for the intercept / resend eavesdropping it was assumed that Eve was 
intercepting only a fraction of the qubits, hence the information that Eve possess 
in this case should be viewed as an average information on the full key. In the 
intercept /resend strategy Eve's handlebar for controlling the disturbance D E is by 
intercepting only a fraction of the qubits, naturally she has no information on the 
qubits she doesn't eavesdrop on, whereas on the qubits that she eavesdrop she will 
actually have a lot of information. On the other hand, when Eve uses an ancilla, 
she is interacting with each single qubit and the disturbance Db is determined by 
the strength of her interaction (which is assumed to be the same for all the qubits). 

However, a couple of conclusions can be made: when Eve performs intercept/ re- 
send eavesdropping on all the transmitted qubits she introduces a disturbance 
Db = 1/4 independently of the measurement she has chosen. Considering now 
the eavesdropping strategy with the ancilla: in order to get the same amount of 
information as for the intercept/resent eavesdropping intercepting all qubits, Eve 
will introduce a disturbance which is twice as big, namely 1/2. At first it may seem 
curious that Eve by performing two so different eavesdropping strategies will end 
up with the same amount of information. However, is should be remembered that 
the optimal eavesdropping strategy is symmetric with respect to Eve and Bob and 
that when the disturbance is D B = 1/2 it corresponds to interchanging Eve and 
Bob. This basically means that Eve keeps the qubit sent by Alice and prepares a 
new qubit at random in one of the four states and sends it to Bob. Which makes it 
immediately clear that in this situation Eve's information corresponds to the infor- 
mation she would have gotten in the intercept /resend eavesdropping — but since 
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she sends Bob one of the four states at random, she obviously introduce a much 
higher disturbance. 

As of today, the scenario we have considered here is actually quite realistic, 
since there is still a long way before having quantum memories which will allow an 
eavesdropper to store her ancilla for the required amount of time. The eavesdropper 
will then be forced to perform her measurement immediately, and as we have just 
seen in this situation a simple intercept /resend eavesdropping strategy is actually 
what will optimize her information. 
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